DIRAS TAKE
Urgent: this CVE is on CISA’s Known Exploited Vulnerabilities list with a near-term federal remediation due date, and public exploit code exists—treat exposed developer instances as high priority for immediate mitigation.
What is CVE-2025-62593?
Attackers can execute arbitrary code against Ray developer instances by luring a developer’s browser to a crafted site; CVE-2025-62593. The flaw affects Ray releases prior to 2.52.0 (< 2.52.0) and requires only network access to the developer machine plus user interaction (a developer visiting a malicious webpage or receiving malvertising) and can be chained with a DNS rebinding attack targeting Firefox and Safari. The vulnerability stems from an insufficient browser-based guard that trusts the User-Agent header and enables code injection from web content.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Which versions of Ray-Project Ray are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| ray | < 2.52.0 |
Is CVE-2025-62593 being exploited?
CISA added CVE-2025-62593 to the Known Exploited Vulnerabilities catalog on 2026-08-17; U.S. federal agencies were required to apply mitigations or fixes by 2026-08-20. Public exploit code for this vulnerability is available.
How to fix CVE-2025-62593
- Restrict exposure of Ray development instances from the internet and block access to developer ports from untrusted networks.
- Follow the vendor’s guidance and apply any recommended mitigations immediately; if mitigations are unavailable, discontinue use of exposed instances.
- Prevent developers from visiting untrusted websites on hosts running Ray and segregate development hosts from general web browsing.
- Monitor logs and network activity for signs of DNS rebinding attempts, suspicious fetch requests, and unexpected process execution on developer hosts.
Frequently asked questions
Is CVE-2025-62593 being actively exploited?
CISA added CVE-2025-62593 to its Known Exploited Vulnerabilities catalog on 2026-08-17 and required federal remediation by 2026-08-20; public exploit code is also available.
Which Ray versions are affected by CVE-2025-62593?
Ray releases before 2.52.0 (< 2.52.0) are listed as affected.
Is there a patch for CVE-2025-62593?
As of 2026-09-29 there is no vendor patch flagged in the facts; follow vendor guidance and apply mitigations or discontinue exposed instances if fixes are not available.
Does CVE-2025-62593 require authentication?
No authentication is required, but the vulnerability requires user interaction—a developer must visit a malicious webpage or encounter malvertising for exploitation.
References
- nvd.nist.gov/vuln/detail/CVE-2025-62593
- cve.org/CVERecord?id=CVE-2025-62593
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-62593
- github.com/ray-project/ray/security/advisories/GHSA-q279-jhrf-cc6v
- github.com/ray-project/ray/commit/70e7c72780bdec075dba6cad1afe0832772bfe09
- All Ray-Project CVEs on CVE Radar
- CVEs published in September 2026